CVE-2012-3494

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
23/11/2012
Last modified:
11/04/2025

Description

The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:citrix:xenserver:*:-:*:*:*:*:x64:* 6.0.2 (including)
cpe:2.3:a:citrix:xenserver:*:-:*:*:*:*:x86:* 6.0.2 (including)
cpe:2.3:o:xen:xen:4.0.0:-:*:*:*:*:x64:*
cpe:2.3:o:xen:xen:4.0.0:-:*:*:*:*:x86:*
cpe:2.3:o:xen:xen:4.1.0:-:*:*:*:*:x64:*
cpe:2.3:o:xen:xen:4.1.0:-:*:*:*:*:x86:*
cpe:2.3:o:xen:xen:4.2.0:-:*:*:*:*:x64:*
cpe:2.3:o:xen:xen:4.2.0:-:*:*:*:*:x86:*


References to Advisories, Solutions, and Tools